Skip to content
CAI
Software that uses CAICheck a score

vortico/flama

60.4

Adequate · 22 September 2026

36.7k

lines of production code

Python

with Rust, TypeScript

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Flama is a high-performance Python web framework designed for serving machine learning models and large language models via HTTP, WebSocket, and JSON-RPC protocols. It provides a modular architecture with built-in support for declarative REST resources, domain-driven design repositories, and JWT-based authentication. The system features a Rust-accelerated core for low-level I/O and serialization, enabling efficient handling of streaming LLM outputs, model serialization, and complex request parsing.

How it got here

2018–2024 — Flama 2.0 framework rewrite

25 changes.

The project underwent a comprehensive architectural overhaul, migrating from a legacy Starlette-based integration to a modular, Rust-accelerated core with native support for Python 3.14. This period introduced a declarative resource system, pluggable schema adapters for Pydantic, Marshmallow, and Typesystem, and a complete Domain-Driven Design infrastructure including repositories and workers. Concurrently, the build tooling was modernized by replacing Poetry with uv and Ruff, streamlining the development workflow and CI/CD pipeline.

2025–2026 — v2 architecture and LLM serving

70 changes.

The framework underwent a major architectural overhaul to version 2.0, introducing a new modular routing and endpoint system alongside a comprehensive HTTP foundation. Significant effort was directed toward building a robust machine learning serving layer, featuring pluggable LLM dialects, engine backends, and model serialization protocols. This period also included extensive CLI enhancements, security improvements, and the addition of stateless MCP server support.

Features

Add Flama documentation and chatbot template applications

This change introduces new template applications for generating Flama documentation and chatbot interfaces. The documentation app integrates the Scalar API Reference React library to render interactive API docs, supported by custom CSS styling and a data layer for configuration. The chatbot app provides the HTML entry point and layout structure for a chat interface. Both applications share a common UI foundation, including a responsive navigation menu, a footer with social links, and base styles that include KaTeX support for LaTeX math rendering.

lib/templates/src · high confidence

Add JWKS key resolver for authentication

Introduces the JWKSResolver component in the authentication module, enabling the system to fetch and cache JSON Web Key Sets (JWKS) from an issuer's URL to verify token signatures. This resolver handles key caching with configurable TTLs, manages concurrent fetches to avoid overloading the issuer, and supports a fallback default key for seamless transitions between fixed secrets and published keys.

flama/authentication/resolvers · high confidence

Add Pydantic schema library support

Users can now define request and response schemas using Pydantic models. This change introduces a new adapter that integrates Pydantic's validation and JSON Schema generation into the framework, enabling features such as file uploads in request bodies and proper handling of nested schemas.

_flama/schemas/\libs/pydantic · high confidence

EdDSA (Ed25519) support added to JSON Web Signatures

The crypto module now supports EdDSA (Ed25519) for signing and verifying JSON Web Signatures (JWS) in addition to existing HMAC algorithms (HS256, HS384, HS512). This allows users to generate and verify tokens using asymmetric key pairs, where a private key signs the token and the corresponding public key verifies it, enabling scenarios where only the public key needs to be published for verification.

flama/crypto · high confidence

Initial support for Domain-Driven Design (DDD) components and exceptions

This change introduces the foundational structure for Domain-Driven Design within the Flama framework. It adds a new \flama.ddd\ package that exposes key components, including a \WorkerComponent\ for dependency injection of DDD workers, and a set of standardized exception classes (\RepositoryException\, \NotFoundError\, \IntegrityError\, etc.) to handle domain-specific errors consistently.

flama/ddd · high confidence

Introduce Brotli and Gzip compression codecs with header negotiation

The compression module now provides dedicated codecs for Brotli and Gzip, allowing responses to be compressed using these algorithms. A new negotiator inspects the client's Accept-Encoding header to automatically select the best available backend, raising an error if no supported encoding is found. This ensures that response bodies are efficiently compressed according to client capabilities.

flama/codecs/compression · high confidence

Introduce DDD HTTP and SQLAlchemy repository implementations

The \flama.ddd.repositories\ package now provides concrete repository implementations for both HTTP resources and SQLAlchemy databases. Users can utilize \HTTPRepository\ and \HTTPResourceManager\ to interact with remote APIs via an injected HTTP client, supporting CRUD operations and pagination. Additionally, \SQLAlchemyRepository\ and \SQLAlchemyTableManager\ are available for database access, offering methods for creating, retrieving, updating, deleting, and listing records with support for clauses and filters. These components extend the existing \BaseRepository\ and are re-exported from the package root for easy import.

flama/ddd/repositories · high confidence

Introduce LLM transport layer for structured message and event handling

This change adds a new transport layer in \flama/models/transport\ that standardizes how LLM inputs and outputs are structured. For inputs, it defines canonical message types (System, User, Assistant, Tool) and a \Shape\ system that supports three modes: \raw\ (verbatim prompt), \chat\ (single-turn with optional system prompt), and \conversation\ (multi-turn history), all of which can include tool definitions. For outputs, it introduces a typed event stream (\StartEvent\, \TextEvent\, \ToolEvent\, \TraceEvent\, \StopEvent\) and an \EventBuffer\ engine that processes these events through a renderer strategy, handling lifecycle markers, text chunks with channel tagging, and tool calls.

flama/models/transport · high confidence

Introduce Marshmallow schema library adapter

Users can now use Marshmallow schemas for request validation, response serialization, and OpenAPI documentation generation within Flama. This change adds a new adapter layer in \flama/schemas/\_libs/marshmallow\ that integrates the \marshmallow\ library, exposing \Schema\ and \Field\ classes along with a \MarshmallowAdapter\ for type conversion and JSON Schema generation. It also includes a custom \File\ field to handle binary file uploads in request bodies, mapping them to Flama's \UploadFile\ data structure.

_flama/schemas/\libs/marshmallow · high confidence

Introduce chatbot template with rich Markdown rendering and Gemini-style conversation layout

The chatbot template application now renders GitHub-flavored Markdown with support for LaTeX math (via KaTeX) and Mermaid diagrams, alongside a Gemini-style conversation interface that pins the latest user prompt to the top of the viewport and provides a floating jump-to-latest button. The chat experience includes collapsible thinking and tool-call blocks, message actions (copy, edit, regenerate), and a streaming composer with auto-expanding input.

lib/templates/src/apps/chatbot · high confidence

Introduce foundational middleware package with built-in implementations

Flama now includes a new \flama.middleware\ package that provides a structured way to extend application behavior. This release introduces a base \Middleware\ class and a \MiddlewareStack\ for managing the ASGI pipeline, along with several ready-to-use middleware components: \CORSMiddleware\ for handling cross-origin requests, \CompressionMiddleware\ for response body compression (Brotli/Gzip), \SessionMiddleware\ for signed cookie-based sessions, \TrustedHostMiddleware\ for host header validation, \HTTPSRedirectMiddleware\ for enforcing secure connections, \CorrelationIdMiddleware\ for request tracing, and \BaseHTTPMiddleware\ as a hook-based template for custom logic.

flama/middleware · high confidence

Introduce modular ML and LLM engine backends

The \flama/models/engine/backend\ package now provides a structured, framework-agnostic adapter layer for model inference. It introduces abstract base classes for both LLM and traditional ML workloads, with concrete implementations for LLM runtimes (vLLM and MLX) and ML frameworks (PyTorch, scikit-learn, TensorFlow, and HuggingFace Transformers). This change enables the engine to automatically detect and load the appropriate backend based on the model artifact's metadata and the available runtime dependencies on the host system.

flama/models/engine/backend · high confidence

Introduce pluggable schema library abstraction with Pydantic, Typesystem, and Marshmallow support

The \flama/schemas\ package has been refactored to support multiple underlying schema validation libraries. Users can now choose between Pydantic, Typesystem, or Marshmallow as the schema backend, with the system automatically detecting and using the first available library or allowing explicit configuration via the \schema\_library\ setting. This change introduces a new adapter interface (\flama.schemas.adapter.Adapter\) that abstracts schema operations, enabling the framework to remain agnostic to the specific validation engine while maintaining consistent behavior for input validation, output serialization, and OpenAPI schema generation.

flama/schemas · high confidence

Introduce stateless MCP server support with Tasks, Elicitation, and Apps extensions

Flama now includes a new MCP module that implements the stateless 2026-07-28 protocol, removing the traditional initialize handshake in favor of self-contained requests carrying protocol version and client identity in the \\_meta\ object. This update adds support for the Tasks extension (allowing long-running tool calls with background runners and status tracking), the Elicitation extension (enabling mid-call input gathering via \Elicit\ and \Elicitation\ types), and the MCP Apps extension (supporting prefetchable UI templates). The module also introduces routing headers (\Mcp-Method\, \Mcp-Name\) for gateway routing, W3C trace context propagation for distributed tracing, and a new \MCPModule\ for registering servers, tools, resources, and prompts.

flama/mcp · high confidence

Introduce structured model layer with lazy loading and streaming support

The \flama/models\ package has been restructured to provide a unified, lazy-loading interface for both ML and LLM artifacts. Models are now wrapped in \BaseModel\ (with \MLModel\ and \LLMModel\ subclasses) that defer heavy deserialization until explicitly loaded or accessed, exposing metadata and bundled artifacts via cheap introspection properties. These models are integrated into the application lifecycle through \ModelComponent\ and \ModelsModule\, which handle dependency injection, sequential startup loading to manage memory, and automatic routing to \MLResource\ or \LLMResource\ based on the artifact's family. Additionally, a new \StreamsRegistry\ and \StreamsBackend\ system (including \FileStreamsBackend\) has been added to persist and manage streaming events for LLM generations, ensuring durable cold storage and cleanup of stream data.

flama/models · high confidence

Introduce typesystem adapter for schema validation and serialization

This change adds a new adapter layer in the typesystem library that bridges Flama's schema system with the external 'typesystem' package. It provides concrete implementations for building fields and schemas, validating input data, serializing outputs, and generating JSON Schema definitions. The adapter also introduces support for file uploads within request body schemas and handles enum types for parameters and resource filtering, enabling consistent schema handling across the framework.

_flama/schemas/\libs/typesystem · high confidence

Introduces DDD Worker abstraction for HTTP and SQLAlchemy units of work

The \flama/ddd/workers\ module now provides a structured way to manage units of work for Domain-Driven Design repositories. It introduces a \BaseWorker\ metaclass that automatically collects repository annotations and manages their lifecycle within a unit of work. Specific implementations include \HTTPWorker\, which initializes a Flama HTTP client and passes it to repositories, and \SQLAlchemyWorker\, which manages async database connections and transactions (with a \DependencyNotInstalled\ error if SQLAlchemy is missing). A generic \Worker\ is also provided for cases requiring no specific setup.

flama/ddd/workers · high confidence

Introduces a pluggable wire dialect system for Anthropic, Ollama, and native LLM integrations

The \flama/models/wire\ module now provides a structured dialect framework that standardizes how Flama translates between its internal L2 event model and external LLM wire formats. This change adds specific dialect implementations for Anthropic (supporting messages API, thinking blocks, and tool use), Ollama (supporting both chat and generate APIs with image handling), and a native Flama dialect (stream-only SSE with resume capabilities). It establishes base abstractions for parsing, rendering, and assembling wire payloads, allowing the system to correctly handle provider-specific shapes like Anthropic's multi-part tool results or Ollama's sibling image fields.

flama/models/wire · high confidence

Introduction of WebSocket message codecs and encoding negotiator

This change introduces a new modular system for handling WebSocket message decoding within the Flama framework. It adds a base \WebsocketsCodec\ class along with specific implementations for \bytes\, \text\, and \json\ message formats, each handling their respective data types and raising appropriate errors for malformed input. Additionally, a \WebSocketEncodingNegotiator\ is provided to automatically select the correct codec based on the requested encoding, allowing applications to seamlessly process different WebSocket payload types.

flama/codecs/websockets · high confidence

Introduction of core utility modules for routing, encoding, and I/O

The \flama.\_core\ package now exposes a set of foundational modules including \route\_table\ and \url\ for path matching and resolution, \json\_encoder\ for JSON serialization, \compression\ for data handling, \cookies\ for header management, \crypto\ for signing operations, \multipart\ for file upload parsing, and \http\ for content-type parsing. These additions provide the underlying infrastructure for request processing and response generation within the framework.

_flama/\core · high confidence

Introduction of foundational HTTP package with request components and data structures

The flama/http module has been introduced as a new foundational package, providing core HTTP data structures (such as Headers, QueryParams, and State) and a set of dependency-injection components (including MethodComponent, URLComponent, and BodyComponent) that resolve request details from the ASGI scope. This change establishes the underlying infrastructure for handling HTTP requests and responses within the framework.

flama/http · high confidence

New CLI commands for model management, serving, and project scaffolding

The CLI now includes dedicated commands to manage and run machine learning models and applications. Users can download and package models from HuggingFace Hub into local artifacts using the new \get\ command, which handles concurrent downloads and safe path validation. The \model\ command allows inspecting and running packaged models directly from the command line, supporting both traditional ML and LLM artifacts with configurable channel scanners and tool parsers. Additionally, \serve\ and \run\ commands provide ways to serve models or applications via HTTP, while \start\ simplifies project initialization by generating configuration files. An \upgrade\ command is also available to migrate existing Flama codebases to newer versions with preview and apply modes.

_flama/\cli/commands · high confidence

New HTTP request and WebSocket connection abstractions

The \flama.http.requests\ package has been introduced, providing new \Request\ and \WebSocket\ classes that wrap ASGI scopes to offer a high-level API for handling HTTP and WebSocket connections. Users can now access request details such as headers, query parameters, cookies, and body content (including JSON and multipart form data with file upload support) through a consistent interface, while WebSocket interactions are managed via a state machine that enforces valid protocol transitions for sending and receiving messages.

flama/http/requests · high confidence

New HTTP response types for streaming, structured APIs, and file serving

The framework now provides a comprehensive set of HTTP response classes in the \flama.http.responses\ module. Users can serve files with \FileResponse\ (including HTTP range requests and ETag support), stream data via \NDJSONResponse\ and \ServerSentEventResponse\, and return structured API payloads with \APIResponse\ and \JSONRPCResponse\. Additional built-ins include \OpenAPIResponse\, \HTMLTemplateResponse\ (using Jinja2 with custom delimiters), and standard \JSONResponse\, \PlainTextResponse\, \HTMLResponse\, and \RedirectResponse\.

flama/http/responses · high confidence

New JWT authentication implementation with claim validation

The \flama/authentication/jwt\ module now provides a complete JSON Web Token implementation. This includes a \JWT\ class for encoding and decoding tokens, along with a \claims\ module that validates standard JWT claims such as expiration (\exp\), not-before (\nbf\), and issued-at (\iat\). The implementation ensures that decoded tokens retain their raw encoded form for potential reuse in downstream services.

flama/authentication/jwt · high confidence

New JWT-based authentication middleware and token components

The flama/authentication package introduces a new authentication system built on JWTs. It provides AccessTokenComponent and RefreshTokenComponent to resolve tokens from HTTP headers or cookies, supporting both static secrets and dynamic key resolvers. An AuthenticationMiddleware enforces route-level access control by checking user permissions and roles against route tags, while handling ignored URL patterns and returning appropriate 403 or 401 responses.

flama/authentication · high confidence

New LLM codec and decoder engine backends

The LLM engine now includes a new codec and decoder subsystem that handles streaming output from various LLM backends. This introduces a state machine (FSM) in the codec to process text deltas, manage channel states (like reasoning/thinking channels), and detect tool calls using configurable scanners and parsers. The decoder supports multiple channel and tool marker formats (e.g., Harmony, Think, Tool Call, Pythonic) and body parsers (JSON Object/Array/Sequence, Call Notation, Tag Notation, Pythonic) to correctly interpret model outputs. This change adds the core infrastructure for handling complex LLM responses, including reasoning channels and tool use, across different engine backends.

flama/models/engine/llm · high confidence

New LLM serving layers and resource abstractions

The \flama/models/resources\ package now provides a structured serving layer system for Large Language Models, introducing base resource classes (\BaseLLMResource\, \LLMResource\) and a metaclass (\LLMResourceType\) that dynamically wires HTTP routes based on the selected protocol. This change adds four concrete serving implementations—Native, OpenAI, Ollama, and Anthropic—each exposing specific endpoints (e.g., OpenAI's \/v1/chat/completions\, Ollama's \/api/chat\, Anthropic's \/v1/messages\) with support for both buffered responses and streaming (SSE/NDJSON). The resources also include an \InspectMixin\ for introspection and handle dialect-specific parsing, tool support, and reasoning capabilities, allowing users to serve LLMs via their preferred API standard.

flama/models/resources · high confidence

New Marshmallow schema definitions for LLM dialects and core utilities

The schema library now includes dedicated Marshmallow schemas for Anthropic, Ollama, and OpenAI LLM dialects, alongside native content-part handling (text, image, audio) and ML/pagination structures. These schemas define the input and output shapes for chat, generation, and model-listing endpoints, enabling consistent validation and OpenAPI documentation for these specific provider interfaces.

_flama/schemas/\libs/marshmallow/schemas · high confidence

New Pydantic and Typesystem schema libraries for LLM dialects and core types

This change introduces two new schema libraries—Pydantic and Typesystem—located in \flama/schemas/\_libs/\. These libraries define the data models for the platform's LLM serving capabilities, covering Anthropic, OpenAI, Ollama, and a native dialect, as well as core types like API errors, pagination, and ML predictions. The schemas are registered in a shared \SCHEMAS\ singleton, providing the validation structures for request and response bodies across these different model providers.

_flama/schemas/\_libs/pydantic/schemas, flama/schemas/\libs/typesystem/schemas · high confidence

New Rust-based core library for Flama

A new native Rust extension module (\flama.\_core\) has been added to the core library, exposing high-performance primitives for Python via PyO3. This module introduces dedicated submodules for streaming compression (supporting gzip, zstd, brotli, and tar), HTTP cookie parsing and serialization, EdDSA (Ed25519) cryptographic signing, fast JSON encoding with support for special Python types (like \Decimal\ and \datetime\), and high-speed route resolution using segment-based path matching. Additionally, it provides ASGI-aware multipart and URL-encoded body parsers that stream file uploads to disk to manage memory usage efficiently.

lib/core · high confidence

New config tool for reading from files or environment variables

Introduces a new \Config\ class in \flama/config\ that retrieves parameters from environment variables, config files (INI, JSON, YAML, TOML), or explicit defaults, with support for type casting and dataclass conversion. The module also includes a \FileDict\ structure for loading file formats, specialized field types like \Secret\ and \URL\, and loaders for various file formats, including a compatibility layer for TOML on Python versions lower than 3.11.

flama/config · high confidence

New debug error pages with traceback and request inspection

The debug application now includes dedicated 404 and 500 error pages that render detailed diagnostic information. The 500 error page displays the error title, a scrollable traceback viewer that auto-centers the selected frame, and tables for the current request (path, method, headers, cookies) and environment (Python version, platform). The 404 page shows the request details and a hierarchical URL tree of application endpoints. These pages are built from new React components (ErrorTraceback, RequestTable, EnvironmentTable, URLTree) and data classes that parse template variables for error context.

lib/templates/src/apps/debug · high confidence

New debug middleware and error context data structures

The \flama/debug\ package now provides the core data structures and middleware for the application's debug and error-handling capabilities. \data\_structures.py\ introduces frozen dataclasses to capture detailed context for errors (\ErrorContext\) and not-found scenarios (\NotFoundContext\), including request details, environment info, and traceback frames. \middleware.py\ implements \ServerErrorMiddleware\ and \ExceptionMiddleware\ to intercept exceptions; in debug mode, these render HTML error pages (such as the new 404 and 500 templates) for browser clients, while returning structured API or plain-text responses otherwise.

flama/debug · high confidence

New declarative resource system with CRUD mixins and filtering

The \flama/resources\ package introduces a new declarative way to define REST resources. Users can now create resources by subclassing \RESTResource\ (which provides \CreateMixin\, \RetrieveMixin\, \UpdateMixin\, \DeleteMixin\, and \ListMixin\) or by using the \ResourcesModule\ to register resources. This system automatically generates routes based on the resource's model (SQLAlchemy \Table\) and schemas, supports filtering with various operators (eq, gt, lt, etc.), and integrates with the DDD worker for repository management.

flama/resources · high confidence

New limit-offset and page-number pagination strategies

The pagination module now provides two distinct strategies for paginating resource views: a limit-offset approach (LimitOffsetPaginator) and a page-number approach (PageNumberPaginator). Both strategies are implemented as decorators that wrap view functions, automatically injecting query parameters (limit/offset or page/page\_size) and transforming the response into a structured JSON format containing metadata and a data array. This allows developers to easily paginate API responses using either cursor-style or page-based navigation without manually handling slicing or response formatting.

flama/pagination/paginators · high confidence

New paginator object for declarative pagination

The pagination module now exposes a \paginator\ singleton object that allows developers to apply pagination to resource methods using either the \apply\ method or the \paginated\ decorator. This change introduces a structured way to handle \limit\_offset\ and \page\_number\ pagination strategies, automatically wrapping the target function to return a \PaginatedResponse\ and managing the associated schema definitions.

flama/pagination · high confidence

New telemetry middleware for request auditing

A new \TelemetryMiddleware\ has been added to the \flama/telemetry\ module, enabling the collection of audit data for HTTP and WebSocket requests. The middleware captures request and response details (headers, cookies, query/path parameters, and bounded body content) along with authentication status and endpoint metadata. Users can configure the middleware with \before\ and \after\ hooks to process telemetry data, set a \max\_body\ limit to prevent unbounded payload capture, and exclude specific routes using path patterns or route tags.

flama/telemetry · high confidence

Removals

Removal of legacy Starlette API integration layer

The \starlette\_api\ package has removed its custom integration layer for Starlette, specifically deleting the \applications.py\, \components.py\, \endpoints.py\, \exceptions.py\, and \injector.py\ modules. This eliminates the library's internal dependency injection system (\Injector\), custom \Component\ base class, and the \Starlette\ application wrapper that previously handled HTTP and WebSocket routing with automatic injection. Users relying on these specific classes for dependency injection or application setup will need to migrate to native Starlette patterns or alternative solutions, as the library no longer provides this abstraction.

_starlette\api · high confidence

Architecture

Centralized type definitions for Flama framework components

The \flama/types\ package has been introduced to provide a unified location for type aliases, protocols, and data structures used across the framework. This change consolidates definitions for HTTP methods (including the new QUERY method), ASGI scopes and handlers, application status, routing, schemas, pagination, and serialization protocols into a single importable module, simplifying type management for developers.

flama/types · high confidence

Behavioural changes

Automated v1-to-v2 migration tooling for Flama codebases

The internal upgrade tool now provides automated migration paths from Flama 1.x to 2.0 and 2.2. The v2 migration automatically rewrites import statements to reflect new module locations (e.g., moving validation logic to \flama.schemas\ and HTTP components to \flama.http\), renames symbols (such as \ModelResource\ to \MLResource\ and \GZipMiddleware\ to \CompressionMiddleware\), and updates call patterns (like unwrapping the old \Middleware\ wrapper and making \content\ a positional argument for response classes). It also flags removed symbols and private modules that require manual attention. The v2.2 migration specifically updates \HMACAlgorithm\ calls to use JWA algorithm names (e.g., \HS256\) instead of hash constructors.

_flama/\upgrade · high confidence

Benchmark results for Flama v2.2.2 and historical versions are now published

The benchmarks directory now includes a comprehensive README documenting performance metrics for the Flama framework, along with JSON result files for versions 2.0.0 through 2.2.2. These results, measured in CI using Valgrind/Callgrind, provide deterministic, hardware-independent CPU cost estimates (estimated cycles and instruction counts) for key operations including JSON serialization, routing, schema validation, dependency injection, middleware overhead, compression, streaming, and LLM tool-call parsing. The latest data for v2.2.2 shows stable performance across 34 tests compared to v2.2.1, with most metrics unchanged within a 5% threshold.

benchmarks · high confidence

CLI interface refactored with rich-themed help and error rendering

The Flama CLI has been restructured to use a custom Click group and command classes that leverage the Rich library for enhanced visual output. Users will now see a themed banner with the Flama logo and version number on help screens, while usage errors and help messages are rendered in styled panels and tables for better readability. The CLI entry point now explicitly registers commands (get, model, run, serve, start, upgrade) and handles specific Click exceptions to ensure consistent, formatted output for both help and error states.

_flama/\cli · high confidence

Conditional LLM decoder initialization in CLI app template

The CLI app template now conditionally imports and instantiates the LLM Decoder only when a model requires a channel scanner, tool scanner, or tool parser. This prevents unnecessary decoder creation for models that do not need these specific capabilities, optimizing the generated application structure.

_flama/\cli/templates · high confidence

Dependency injection system restructured with caching and context support

The dependency injection subsystem has been rewritten to support a tree-based resolution model, allowing dependencies to be resolved in a hierarchical manner. A new injection context mechanism enables values to be provided via typed fields, while a per-request cache for component resolution values improves performance by avoiding redundant computations. The injector now uses LRU caches for both function signatures and resolved values, keyed by parameter and context, to optimize repeated injections.

flama/injection · high confidence

Engine module initialization updated

The engine module's initialization file has been replaced with an empty file, effectively clearing any previous exports or side effects from this location.

flama/models/engine · medium confidence

Flama framework core restructured with modular architecture and new capabilities

The Flama application has been restructured into a modular system, introducing a \Modules\ registry and a \MiddlewareStack\ to extend functionality. This change brings a new \Client\ for testing and interacting with Flama apps, a \BackgroundTask\ system supporting both thread and process concurrency, and a \Lifespan\ handler that orchestrates startup and shutdown events. The framework now includes built-in caching (\LRUCache\, \TTLCache\), improved URL routing with typed path parameters, and compatibility shims for older Python versions. Additionally, the \FlamaWorker\ is now conditionally imported to avoid hard dependencies on SQLAlchemy, and the application supports recursive mounting of other Flama apps.

flama · high confidence

Migrate build tooling from Poetry to uv and modernize CI/CD configuration

The project has replaced Poetry with uv for dependency management, evidenced by the removal of the old \pyproject.lock\ and the addition of a new \uv.lock\ file. This migration is accompanied by a significant overhaul of the development workflow: the legacy \build.py\ script, \setup.cfg\, \tox.ini\, and \.travis.yml\ have been removed and replaced with a modular \Makefile\ that delegates to dedicated shell scripts in the \scripts/\ directory. Additionally, the commit history notes the replacement of flake8, black, and isort with ruff for linting and formatting, and the CI configuration now supports Python 3.14 while dropping support for Python 3.9.

(repo-wide) · high confidence

Migrate templates to pnpm and @vortico/ui

The templates directory has been restructured to use pnpm as the package manager and adopt the @vortico/ui design system. This change introduces a new build configuration using Webpack with Babel, PostCSS, and Tailwind CSS, alongside ESLint and Prettier configurations sourced from @vortico/config. The setup ensures consistent coding standards and modern build tooling for template development.

lib/templates · high confidence

New HTTP request body decoding infrastructure

The HTTP codec subsystem has been restructured to use a pluggable, negotiator-based architecture for decoding request bodies. This change introduces a base \Codec\ interface and an \HTTPContentTypeNegotiator\ that selects the appropriate decoder based on the \Content-Type\ header. Specific decoders are now provided for JSON (\JSONDataCodec\), URL-encoded forms (\URLEncodedCodec\), and multipart file uploads (\MultiPartCodec\), with the multipart decoder supporting configurable limits for file count, field count, and body size to prevent resource exhaustion.

flama/codecs/http · high confidence

New Router implementation for URL resolution and request handling

The \flama/routing\ module now introduces a new \Router\ class that manages route registration, URL resolution, and request dispatching for HTTP and WebSocket scopes. This component replaces previous routing logic by utilizing a core \RouteTable\ for efficient path matching and integrates with the application's component injection system, allowing developers to define routes via decorators or explicit methods while handling lifespan events and scope management.

flama/routing · high confidence

New endpoint dispatch system for HTTP, WebSocket, and JSON-RPC

The framework introduces a new endpoint architecture in the \flama/endpoints\ module, replacing previous handling mechanisms with a structured dispatch system. This change adds \HTTPEndpoint\ for standard HTTP request routing, \WebSocketEndpoint\ for managing connection lifecycle events (connect, receive, disconnect), and \JSONRPCEndpoint\ for handling JSON-RPC method calls with automatic envelope parsing and dependency injection. A shared \BaseEndpoint\ class standardizes scope handling and context building, while \components.py\ provides reusable injection components for JSON-RPC parameters, enabling developers to define handlers with typed dependencies across all three transport types.

flama/endpoints · high confidence

New modular routing implementation with dedicated HTTP, WebSocket, and Mount route classes

The routing layer has been restructured into a new, modular package under \flama/routing/routes\. This change introduces distinct route classes for different protocols: \Route\ for HTTP endpoints, \WebSocketRoute\ for WebSocket connections, and \Mount\ for nested ASGI applications. Each class includes its own endpoint wrapper (e.g., \HTTPFunctionWrapper\, \WebSocketFunctionWrapper\) that handles request context, injection, and response building specific to its protocol. The base \BaseRoute\ and \BaseEndpointWrapper\ classes provide shared functionality like path matching, parameter resolution, and ASGI interface compliance, while the \\_\init\\_.py\ exposes these components for public use. This separation allows for more precise handling of HTTP methods, WebSocket states, and mounted application scopes.

flama/routing/routes · high confidence

New serialization protocol v2 with enhanced model capabilities and security

The serialization module has been refactored to introduce protocol v2, which supports versioned serialization and includes a new compression module. This change adds detailed model capability detection (including multimodal flags for LLMs like image, audio, and video support) and introduces security hardening by validating artifact names and paths to prevent unsafe file extraction (CWE-22). Users benefit from more robust model packaging, explicit capability advertising in manifests, and safer deserialization processes.

flama/serialize · high confidence

New unified model serialization protocol with framework-specific serializers

The serialization system has been rebuilt to support a new v2 protocol, introducing a modular serializer architecture for PyTorch, scikit-learn, TensorFlow, and HuggingFace Transformers. PyTorch models are now serialized using the new torch.export API, while Transformers models are packaged as tar archives and include enhanced capability detection for multimodal features (vision/audio) and reasoning capabilities. This change ensures consistent serialization interfaces across different ML frameworks and improves the accuracy of model capability detection during the serialization process.

_flama/serialize/model\serializers · high confidence

Rebuilt serialization protocol with versioning and v2 support

The serialization system has been refactored to support multiple protocol versions, introducing a new v2 format alongside the legacy v1. The v2 protocol enables support for directory bundles (such as LLM and Transformers models) via a tar-stream model section and allows per-section compression overrides, whereas v1 remains available for backward compatibility with binary-only models. A new base protocol class enforces strict artifact name validation to prevent path traversal vulnerabilities during deserialization, and a factory class now dynamically loads the appropriate protocol implementation based on the version specified in the serialized file.

flama/serialize/protocols · high confidence

Refactored development and build scripts to use uv, Ruff, and Ty

The project's shell scripts have been restructured into a modular set of utilities that replace the previous toolchain. Dependency management and Python execution now use \uv\ (invoked via \uv run\ or \uvx\), while linting and formatting are handled by \ruff\ and type checking by \ty\. The build process supports building or fetching templates from a private registry, and the performance suite now uses Valgrind/Callgrind for deterministic, hardware-independent benchmarking.

scripts · high confidence

Test coverage

Added performance benchmark suite for Flama core components; Added test utility modules for assertions, contexts, and model fixtures; Added unit tests for CLI commands and formatting; Added unit tests for CLI configuration and server components; Added unit tests for DDD repositories and workers; Added unit tests for HTTP and WebSocket request handling; Added unit tests for HTTP components and data structures; Added unit tests for HTTP response classes; Added unit tests for HTTP, WebSocket, and JSON-RPC endpoints; Added unit tests for LLM and ML engine backends; Added unit tests for LLM and ML model resources; Added unit tests for LLM engine codec, decoder, markers, and parsers; Added unit tests for LLM serving dialects and base abstractions; Added unit tests for LLM wire dialect base abstractions; Added unit tests for authentication components and resolvers; Added unit tests for codec negotiation and decoding; Added unit tests for configuration, application lifecycle, and core utilities; Added unit tests for core JSON encoding, routing, and URL matching; Added unit tests for crypto algorithms, JWK, and JWS; Added unit tests for debug middleware and data structures; Added unit tests for model serialization components; Added unit tests for request, parameter, return, schema, and file upload validation; Added unit tests for schema library adapters and registries; Added unit tests for schema validation and LLM dialects; Added unit tests for serialization data structures and serializer logic; Added unit tests for serialization protocol v1 and v2; Added unit tests for the Anthropic LLM dialect components; Added unit tests for the Flama upgrade tool and v2 migration codemods; Added unit tests for the LLM transport input and output models; Added unit tests for the OpenAI LLM dialect implementation; Added unit tests for the Resources module; Added unit tests for the dependency injection system; Added unit tests for the models package; Added unit tests for the routing subsystem; Added unit tests for type annotation parsing and model library definitions; Consolidated test infrastructure and removal of legacy dependency injection tests; Unit tests added for MCP server components and endpoints.

Dependencies

Flama 2.2.2: Rust core, Python 3.14 support, and modernized build tooling

This release introduces a new Rust-based core library (flama-core) to handle low-level operations, alongside a major upgrade to the Python project structure. The package now requires Python 3.10–3.14, dropping older versions, and adds explicit support for Python 3.14. Build tooling has shifted from Poetry to uv and maturin, with the Rust code compiled via PyO3. The templates directory now uses pnpm and React 19, and the main package rebrands to 'flama' with Apache-2.0 licensing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 60 (+6.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 93 → 93 (+0.7)
  • Architecture 100 → 95 (-4.7)
  • Maturity 56 → 59 (+3.3)
  • Readiness 47 → 68 (+21.1)
  • Security 65 → 76 (+10.9)
  • Domain Modelling 100 → 94 (-6.1)
  • Accessibility 51 → 51 (+0.0)

Resolved (67)

  • Change coupling: applications.py ↔ jsondata.py (flama/applications.py)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (uv.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (flama/models/resources/serving/llm/openai.py)
  • Duplicated block (10 lines × 2) (flama/serialize/serializer.py)
  • Duplicated block (10 lines × 4) (flama/models/wire/dialect/llm/anthropic/parser.py)
  • Duplicated block (11 lines × 2) (flama/models/resources/serving/llm/ollama.py)
  • Duplicated block (11 lines × 3) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (12 lines × 2) (flama/models/resources/llm.py)
  • Duplicated block (12 lines × 2) (flama/models/resources/serving/llm/openai.py)
  • Duplicated block (12 lines × 2) (flama/routing/routes/http.py)
  • Duplicated block (15 lines × 2) (flama/models/wire/dialect/llm/openai/assembler.py)
  • Duplicated block (15 lines × 3) (flama/serialize/serializer.py)
  • Duplicated block (17 lines × 2) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (26 lines × 2) (flama/pagination/paginators/limit_offset.py)
  • Duplicated block (28 lines × 3) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (37 lines × 2) (flama/models/_base.py)
  • Duplicated block (5 lines × 2) (flama/models/wire/dialect/llm/anthropic/parser.py)
  • Duplicated block (5 lines × 2) (flama/schemas/_libs/marshmallow/adapter.py)
  • …and 47 more

New (81)

  • Conversation.Conversation (cognitive 22) (lib/templates/src/apps/chatbot/components/conversation/Conversation.tsx)
  • Conversation.Conversation (cyclomatic 21) (lib/templates/src/apps/chatbot/components/conversation/Conversation.tsx)
  • Documentation: contradicts the code (benchmarks/README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (flama/models/resources/serving/llm/ollama.py)
  • Duplicated block (10 lines × 2) (flama/models/resources/serving/llm/ollama.py)
  • Duplicated block (10 lines × 3) (flama/models/resources/serving/llm/openai.py)
  • Duplicated block (10 lines × 4) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (10 lines × 4) (flama/models/wire/dialect/llm/anthropic/parser.py)
  • Duplicated block (11–12 lines × 2) (flama/models/resources/serving/llm/ollama.py)
  • Duplicated block (12 lines × 2) (flama/models/resources/llm.py)
  • Duplicated block (13 lines × 2) (flama/models/resources/serving/llm/openai.py)
  • Duplicated block (13 lines × 3) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (14 lines × 3) (flama/serialize/serializer.py)
  • Duplicated block (16 lines × 2) (flama/models/wire/dialect/llm/native/parser.py)
  • Duplicated block (16 lines × 3) (flama/models/resources/serving/llm/anthropic.py)
  • Duplicated block (17 lines × 2) (flama/routing/routes/http.py)
  • Duplicated block (17 lines × 2) (flama/serialize/serializer.py)
  • Duplicated block (20–22 lines × 2) (flama/models/wire/dialect/llm/openai/assembler.py)
  • …and 61 more

Changes since last survey

  • 12 commits — 9 feature/other, 3 fixes

By area

  • (root) — 3 commits
  • benchmarks/README.md — 3 commits
  • flama/authentication — 2 commits
  • tests/unit — 2 commits
  • flama/_upgrade — 1 commit
  • flama/telemetry — 1 commit

Notable commits

  • fix: :bug: JWK resolver
  • fix: :bug: Keep raw token on decode (#282)
  • fix: :bug: Unbounded payload capture in the telemetry middleware (#274)
  • change: :bookmark: 2.2.0 [skip ci]
  • change: :bookmark: 2.2.1 [skip ci]
  • change: :bookmark: 2.2.2 [skip ci]
  • change: :chart_with_upwards_trend: Add benchmark results for v2.2.0 [skip ci]
  • change: :chart_with_upwards_trend: Add benchmark results for v2.2.1 [skip ci]
  • change: :chart_with_upwards_trend: Add benchmark results for v2.2.2 [skip ci]
  • change: :sparkles: Chained upgrade migrations (#271)
  • change: :sparkles: EdDSA signing for JSON Web Signature (#269)
  • change: :sparkles: Key identity and per-key token verification (#270)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

vortico/flama was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 06287d7fc526c8b926ff38c5aa5f9c8f3dff380d — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.